Security Engineer

Skywarditsolutions

Rockville (MD)

Hybrid

USD 90,000 - 125,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision insurance
401K with 4% employer contribution
Up to $5,000 for professional development
Life and disability insurance
Flexible working hours

Job summary

Skywarditsolutions in Rockville, Maryland, is looking for a Security Engineer dedicated to protecting critical systems. The ideal candidate will have hands-on experience with vulnerability scanning and management tools and support compliance with federal security frameworks.

This role involves automating security processes and working collaboratively within a motivated team to modernize government services. Benefits include fully paid medical insurance, generous paid leave, and a supportive work environment.

Qualifications

  • 3-5 years of experience in security engineering, cybersecurity, or a related role.
  • Hands-on experience with vulnerability scanning and management tools.
  • Comfort scripting and automating in Python or Bash.

Responsibilities

  • Run vulnerability and security scans and prioritize findings.
  • Automate security tooling into CI/CD pipelines.
  • Document vulnerabilities and support remediation tracking.
  • Support compliance with CMS and federal requirements.

Skills

Vulnerability scanning and management
AWS security compliance
Scripting in Python or Bash
Collaboration with stakeholders

Education

Bachelor's degree in computer science, information systems, cybersecurity, or related field

Tools

Tenable
AWS Inspector
Snyk
Trufflehog
GitLeaks

Job description

We are Skyward.

That is, a love for people, for improvement, for human advancement through information technology. We are a people‑centered business with a desire to serve others. We are diverse and unified; creative and collaborative; a collection of complementary, not competing talents. And though on the surface we remain relaxed, beneath, a torrent of energy links us to our civic tech mission.

We stand by our values, and we won’t compromise on any of them.

Integrity: We’re conscientious, intentional, and empathetic. Our words and actions align. That’s our character. Please don’t ask us to play another part, we’re poor actors.

Compassionate: If we may borrow a quote from Theodore Roosevelt: “No one cares how much you know until they know how much you care.” Because our team is thoughtful and supportive, caring deeply for each other, our clients, and our work, this comes naturally.

Inquisitive: We remain students by failing openly and turning lessons into solutions.

Unconventional: For us, life isn’t what happens outside of work. Work happens inside of life and our culture erases the line often dividing the two.

Authentic: Made possible only because we embody the values listed above. We’re relaxed and fun yet intensely curious and driven. Team members are placed with thought, care, and precision to ensure that Trust, Truth, and Transparency continue to represent our brand.

Because of that, we continue Onward, Upward, and Skyward.

About the Role

We need a Security Engineer. Do your friends treat you as the go‑to for their security questions, and do you get a little satisfaction from finding the vulnerability everyone else missed? Are you happiest with your hands on the tools, automating scans, hardening pipelines, and turning a wall of findings into a prioritized plan of attack? If you’d like to put your technical skills and security instincts to work protecting systems that matter, then stop thinking about it and apply!

Come join us if you're motivated to learn from others, to learn from mistakes, to be part of a future‑looking and growth‑oriented team.

Let’s go Skyward together.

Responsibilities
  • Join the team supporting the Centers for Medicare & Medicaid Services (CMS) as it merges and modernizes its enterprise knowledge and data systems into a single, AI‑driven platform.
  • Find and prioritize what matters. Run vulnerability and security scans, then build a clear, prioritized list of weaknesses based on severity, known exploitation, and exploitation probability using intelligence sources like the CISA KEV catalog and EPSS.
  • Automate security into the pipeline. Embed security tooling such as Snyk, Trufflehog/GitLeaks, Tenable, and AWS Inspector into CI/CD so vulnerabilities are caught and reported before they ship.
  • Modernize compliance, hands‑on. Help drive the move toward Continuous ATO (cATO) and near‑real‑time compliance monitoring using AWS Security Hub, Config, and Audit Manager, plus the CMS GRC system of record (CFACTS).
  • Build and feed continuous monitoring. Implement monitoring of production runtime environments for vulnerabilities and compliance drift, and make security and compliance reporting available on demand.
  • Track and close the gaps. Document vulnerabilities, misconfigurations, and compliance deviations, and support POA&M creation and remediation tracking to keep system ATOs healthy.
  • Keep us aligned to the standards. Support compliance with CMS and federal requirements such as NIST RMF, ARS, and IS2P2 within a FISMA Moderate boundary.
  • Harden access. Help implement least‑privilege, role‑based access controls aligned to Zero Trust objectives and support regular access reviews and audits.
  • Raise the flag early. Identify, document, and communicate security risks tied to modernization efforts so they get to the right stakeholders before they become problems.
Qualifications
  • A bachelor’s degree in computer science, information systems, cybersecurity, or a related field.
  • 3–5 years of experience in security engineering, cybersecurity, or a related role.
  • Hands‑on experience with vulnerability scanning and management tools (e.g., Tenable, AWS Inspector, Snyk, Trufflehog, or GitLeaks).
  • Working knowledge of AWS security and compliance services (Security Hub, Config, Audit Manager) or comparable cloud‑native tooling.
  • Familiarity with security compliance and the Authority to Operate (ATO) process, including POA&Ms and continuous monitoring.
  • Understanding of federal security frameworks such as NIST RMF, ARS, or IS2P2 (or a strong willingness to learn them quickly).
  • Comfort scripting and automating in Python or Bash and integrating tooling into CI/CD pipelines.
  • Solid problem‑solving skills and the ability to collaborate across multiple stakeholders.
Additional Qualifications
  • Previous experience supporting CMS.
  • Experience securing AI, NLP, or LLM‑driven systems and the data behind them.

Even if you don’t meet 100% of the qualifications, we encourage you to apply. At Skyward, we’re focused on hiring individuals with the right skills and passion to grow, not just checking off every box.

Benefits
  • Medical, dental, vision insurance (fully paid for employees)
  • 15 days of paid leave
  • 7 days of sick leave
  • 2 days bereavement leave
  • 11 paid Federal holidays
  • Up to 40 hours for jury duty
  • 401K with 4% employer contribution (and no vesting period)
  • Up to 4 weeks of paid paternity and maternity leave
  • Company provided laptop
  • $5,000 per year for professional development
  • $600 per year for technical supplies and equipment
  • $2,000 referral bonus
  • Life and disability insurance
  • HSA and FSA
  • Legal Shield and ID Shield voluntary benefits
  • Opportunity to work in a collaborative, motivated team focused on modernizing government services with cutting‑edge technology and innovative solutions.

At Skyward, we support flexible working hours and remote opportunities to help maintain a healthy work‑life balance for all employees.

Offers of employment with Skyward are contingent upon acceptable results of a background investigation.

Applicants must have the ability to obtain and maintain a Public Trust security clearance due to the nature of our work as a government contractor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Site Reliability Engineer
Site Reliability Engineer

Skywarditsolutions • Rockville (MD)

Hybrid
USD 100,000 - 130,000
Medical, dental, vision insurance
15 days of paid leave
401K with 4% employer contribution
+3
Solutions Architect
Solutions Architect

Skyward IT Solutions, LLC • Rockville (MD)

Hybrid
USD 150,000 - 190,000
Medical, dental, vision insurance (fully paid for employees)
401K with 4% employer contribution
Up to 40 hours for jury duty
+2
Site Reliability Engineer
Site Reliability Engineer

Skyward IT Solutions, LLC • Rockville (MD)

Hybrid
USD 112,000 - 150,000
Medical, dental, vision insurance (fully paid for employees)
401(k) with 4% employer contribution
Up to 4 weeks of paid parental leave
+1
Solutions Architect
Solutions Architect

Skywarditsolutions • Rockville (MD)

Hybrid
USD 120,000 - 150,000
Medical, dental, vision insurance
401K with 4% employer contribution
Professional development funding
+1
Technical Analyst
Technical Analyst

Skyward • United States

On-site
USD 65,000 - 105,000
Medical, dental, vision insurance
401K with employer contribution
Company provided laptop
+1
Cloud Engineer
Cloud Engineer

Skywarditsolutions • Rockville (MD)

Hybrid
USD 100,000 - 130,000
Medical, dental, vision insurance
401K with 4% employer contribution
Flexible working hours
Site Reliability Engineer
Site Reliability Engineer

Skyward • Rockville (MD)

Hybrid
USD 112,000 - 150,000
Fully paid medical, dental, and vision insurance
401(k) with 4% employer contribution
Up to 4 weeks paid paternity and maternity leave
+2
Cloud Engineer
Cloud Engineer

Skyward IT Solutions, LLC • Rockville (MD)

Hybrid
USD 115,000 - 145,000
Medical, dental, vision insurance
15 days paid leave
7 days sick leave
+3
Software Engineer
Software Engineer

Skywarditsolutions • Rockville (MD)

Hybrid
USD 90,000 - 120,000
Medical, dental, and vision insurance
15 days of paid leave
401(k) with 4% employer contribution
+3
Senior Data Scientist
Senior Data Scientist

Skywarditsolutions • Maryland

On-site
USD 110,000 - 145,000
Medical, dental, and vision insurance
15 days of paid leave
401(k) with employer contribution
+1